Name what you are being asked to do
Is the message asking you to pay, enter a password, supply a code, download a file or change account details? Write down the action separately from the story used to justify it.
Practical guide
You do not have to prove a message is fraudulent before pausing. Verify the request through a route you already trust instead of following its instructions.
Explore Cadence's daily courses
We make Cadence, an app for short daily courses built around your goal. Explore the reviewed course library to see its current focus and decide whether it fits what you want to learn.
A text says a parcel cannot be delivered unless you pay a small fee immediately. You are expecting a parcel, so the timing feels convincing. But matching your situation does not establish who sent the message.
The useful skill is choosing a safe verification route. You do not need to become an expert in every scam design, and this exercise does not require opening a suspicious link to investigate it.
The short answer
Pause before opening links or attachments. Reach the organisation through its known app, a saved address or an independently verified contact. Check whether the request is real, then report suspicious messages through the appropriate channel.
The method
The delivery example below is fictional. Apply the same separation to other unexpected requests.
Is the message asking you to pay, enter a password, supply a code, download a file or change account details? Write down the action separately from the story used to justify it.
Urgency is a reason to check the route, not a reason to skip checking. Do not reply with personal information or open an attachment just to establish whether the message is real.
For a parcel, use the retailer's order history or the delivery company's app or website you already know. For a workplace request, contact the person through an established internal channel. Do not use the contact details supplied only in the suspicious message.
If the trusted channel confirms an actual issue, resolve it there. If it does not, use your organisation's reporting process or the service's official guidance. Keep your conclusion specific: this request was not verified through the trusted route.
The security context
NIST describes phishing as deceptive communication intended to obtain sensitive information or prompt harmful action. Its guidance points to checking suspicious requests and using appropriate reporting channels. Familiar branding or a plausible sender name should not replace verification.
Worked example
In our invented case, the retailer's order history says the parcel is still being prepared. There is no matching payment request. You have not proved every detail of the text false, but you have no verified reason to pay through it.
Even if the order history did show a delivery problem, the next step would be to resolve it through that established channel. A real problem does not authenticate an unrelated link claiming to solve it.
If you already acted
If you entered account credentials or payment information, use the provider's official recovery or support route promptly. For a work account or device, tell your security or IT team what happened and follow its incident instructions. Report which action you took instead of spending time guessing whether the message looked convincing enough.
For practice, take an invented urgent request and identify the independent route you would use. Do not experiment on a real suspicious attachment or login page.
From the publisher
We make Cadence. This article teaches a verification habit; your employer's security process and the affected provider's recovery guidance take priority when handling an actual incident.
Put it into practice
We make Cadence, an app for short daily courses built around your goal. Explore the reviewed course library to see its current focus and decide whether it fits what you want to learn.
Questions
No. Judge the request and verify its origin through an independent channel. Good writing is not proof of authenticity.
Check the order through the retailer or delivery service you already use. A plausible situation does not authenticate the message.
You do not need to open it for this method. Navigate independently through a known app or verified address instead.
For an unexpected sensitive request, confirm through an established separate channel. A displayed name alone does not establish who controls the message.
Sources
Try Cadence today
We make Cadence, an app for short daily courses built around your goal. Explore the reviewed course library to see its current focus and decide whether it fits what you want to learn.